CVE-2026-40205

Description

A flaw was found in Dovecot. An attacker with a partially valid OAuth2 token can bypass authorization checks in remote token validation paths. This allows the attacker to authenticate with insufficient permissions, leading to a breach of integrity where the configured authorization policy is not properly enforced.

Mitigation

To mitigate this issue, configure Dovecot to use local OAuth2 token validation instead of remote validation. This ensures that all required scopes are correctly enforced during authentication, preventing unauthorized access with partially valid tokens. Consult Dovecot documentation for specific configuration steps to enable local token validation. A service restart may be required for the changes to take effect.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.9N/A5.9
Attack VectorNetworkN/ANetwork
Attack ComplexityHighN/AHigh
Privileges RequiredLowN/ALow
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityLowN/ALow
Integrity ImpactHighN/AHigh
Availability ImpactNoneN/ANone

Vector

Red Hat: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N

cve.org: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Frequently Asked Questions

Want to get errata notifications? Sign up here.